For Florida law firms
Matter teams and ethical walls, enforced in the database
firm lane · Deterministic — no model call
Current availability
ShippedConfigured and enabled: firm staff of the matter's firm.
- Where it lives
- The matter's Team & walls (/admin/matter/[id]/access) · Firm settings → The firm's walls (/firms/manage/walls) · /api/admin/matter-access
- What unlocks it
- the firm's own staff; the walls change by an attorney or administrator of the firm, or the matter's responsible member
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- ShippedA matter is open to the firm's staff (the default) or team-only: only the people on its team open it, and a team-only matter always keeps a responsible member.
- ShippedAnyone on the firm's staff can be screened from a matter, with the reason on the record; a screen beats every role and every team seat, and nobody lifts their own.
- ShippedThe wall holds in the database on every table that carries a matter and on its stored files: a walled member of the firm reads nothing of the matter — not its page, documents, files, history, AI records, notices, approvals, runs, billing lines or vault records, and not its name in a list, a count, a search or an export.
- ShippedA conflict screen that finds someone on a matter the reader cannot open shows the finding without the name, the role or the matter — a wall never turns a finding into a clear — and that finding is decided by an attorney who can open the matter.
- ShippedA change that shuts someone out also expires their unspent approvals on the matter in the same transaction; every change is kept on the matter's access record.
- ShippedFirm-wide digests (the reminder mail, the daily bell, the Monday briefing), firm API keys and calendar feeds leave out every matter a wall keeps from them.
Limits
- Walls bind the firm's staff: the client always opens their own matter in their portal, and a granted platform support session keeps its own scope rules.
- Walls belong to the firm that set them — a matter transferred to another firm starts open there.
- The register lists the walls on the matters its viewer can open; a matter the viewer is walled from does not appear in it.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| not-authorized | 403 | Only the firm's attorneys and administrators, or the matter's responsible member, change who can open it. |
| firm-staff-only | 403 | A support session reads a firm's walls; only the firm's own staff change them. |
| self-lift | 403 | Nobody lifts their own screen. |
| last-responsible | 409 | A team-only matter keeps a responsible member — name another one first. |
| screened | 409 | A screened person cannot join the team until the screen is lifted, on the record. |
| walled | 409 | An attorney walled from a matter is never assigned it, and never decides a conflict finding on it. |
| unavailable | 503 | The change could not be read or recorded — nothing was changed. |
Evidence
- supabase/migrations/20260926140000_phase10_matter_walls.sql
- supabase/migrations/20260926140100_phase10_screen_results_redaction.sql
- src/app/api/admin/matter-access/route.ts
- src/app/admin/matter/[id]/access/page.tsx
- src/lib/access/walls.ts
- src/lib/conflicts/results.ts
- docs/security/MASTER-PLAN-PHASE10A-2026-09-26.md
Last reviewed 2026-09-26